US2015304736A1PendingUtilityA1

Technologies for hardening the security of digital information on client platforms

Assignee: LAL RESHMAPriority: Jun 4, 2013Filed: Jun 4, 2013Published: Oct 22, 2015
Est. expiryJun 4, 2033(~6.9 yrs left)· nominal 20-yr term from priority
G06F 21/10H04L 2209/24H04L 9/0816H04N 21/64715G06F 21/72
36
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Technologies for hardening the security of digital information on a client device are described. In some embodiments, the client device includes a secure processing environment such as a secure enclave, which may be used to protect digital information on a client platform. The secure environment(s) may also protect assets which may be used to access the digital information. Using the secure processing environment(s), the described technologies may protect digital information as it is provided to, stored on, accessed on, and/or processed for display by a client device, even if the client device may be infested with malware or subject to attack by another entity.

Claims

exact text as granted — not AI-modified
1 - 99 . (canceled) 
     
     
         100 . A client device, comprising: a processor; a memory having encrypted digital information stored thereon, the encrypted digital information being encrypted with a first encryption protocol; a secure processing environment having a client enterprise rights enforcement module (CEREM) and a secure video module (SVM)s stored therein; and media hardware comprising a media memory; wherein: the CEREM is to decrypt said encrypted digital information with one or more decryption keys to obtain plaintext of said digital information within said secure processing environment; said SVM is to: encrypt said plaintext of said digital information using a second encryption protocol; and transmit the digital information encrypted with said second encryption protocol to media hardware; and the media hardware is to decrypt the digital information encrypted with said second encryption protocol to obtain the plaintext of said digital information within media memory, and to encrypt said plaintext within said media memory with a third encryption protocol to produce an encrypted media signal. 
     
     
         101 . The client device of  claim 100 , wherein said SVM is further to process said plaintext of said digital information in said secure processing environment into raw frames, to encrypt said raw frames using said second encryption protocol to produce encrypted frames, and to transmit said encrypted frames to said media hardware. 
     
     
         102 . The client device of  claim 101 , wherein said media hardware is further to decrypt said encrypted frames to obtain said raw frames in said media memory, and to encrypt said raw frames in said media memory with said third encryption protocol to produce said encrypted media signal. 
     
     
         103 . The client device of  claim 100 , further comprising a license sealed to said secure processing environment, the license comprising one or more decryption keys for decrypting said encrypted digital information, wherein the CEREM is to decrypt said encrypted digital information using said one or more decryption keys. 
     
     
         104 . The client device of  claim 100 , further comprising a secure video encryption key (SVEK) sealed to or stored in said secure processing environment and said media memory, wherein:
 said SVM is to use said SVEK to encrypt said plaintext of said digital information within said secure processing environment to produce SVEK encrypted digital information, and to transmit said SVEK encrypted digital information to said media hardware; and   said media hardware is to use said SVEK in said media memory to decrypt said SVEK encrypted digital information, so as to obtain said plaintext of said digital information within said media memory.   
     
     
         105 . The client device of  claim 104 , further comprising an SVEK issuing authority, the SVEK issuing authority to generate said SVEK and transmit said SVEK to said secure processing environment and said media hardware. 
     
     
         106 . The client device of  claim 104  wherein said SVEK is a temporal SVEK. 
     
     
         107 . A method, comprising: decrypting encrypted digital information to obtain plaintext of said digital information within a secure processing environment of a client device, the encrypted information being stored on said client device and encrypted with a first encryption protocol; encrypting said plaintext of said digital information using a second encryption protocol; transmitting the digital information encrypted with the second encryption protocol to media hardware of said client device; decrypting the digital information encrypted with said second encryption protocol to obtain the plaintext of said digital information within a media memory of said media hardware; and encrypting said plaintext within said media memory with a third encryption protocol to produce an encrypted media signal. 
     
     
         108 . The method of  claim 107 , further comprising:
 processing said plaintext of said digital information in said secure processing environment into raw frames;   encrypting said raw frames within said secure processing environment to produce encrypted frames; and   transmitting said encrypted frames to said media hardware.   
     
     
         109 . The method of  claim 108 , further comprising:
 decrypting said encrypted frames with said media hardware obtain said raw frames in said media memory; and   encrypting said raw frames in said media memory with said third encryption protocol to produce said encrypted media signal.   
     
     
         110 . The method of  claim 107 , further comprising decrypting said encrypted digital information with one or more decryption keys in a license sealed to said secure processing environment, so as to obtain said plaintext of said digital information within said secure processing environment. 
     
     
         111 . The method of  claim 107 , wherein a secure video encryption key (SVEK) is stored in said secure processing environment and said media memory, the method further comprising:
 using said SVEK in said second encryption protocol to encrypt said plaintext of said digital information within said secure processing environment to produce SVEK encrypted digital information;   transmitting said SVEK encrypted digital information to said media hardware; and   decrypting said SVEK encrypted digital information with said media hardware using said SVEK in said media memory, so as to obtain said plaintext of said digital information within said media memory.   
     
     
         112 . The method of  claim 111 , wherein the client device further comprises an SVEK issuing authority, the method further comprising:
 generating an SVEK with said SVEK issuing authority; and   transmitting said SVEK from said SVEK issuing authority to said secure processing environment and said media hardware.   
     
     
         113 . At least one machine readable storage medium having stored thereon, individually or in combination, instructions that when executed by at least one processor result in the following operations comprising: decrypting encrypted digital information to obtain plaintext of said digital information within a secure processing environment of a client device, the encrypted information being stored on said client device and encrypted with a first encryption protocol; encrypting said plaintext of said digital information using a second encryption protocol; transmitting the digital information encrypted with the second encryption protocol to media hardware of said client device; decrypting the digital information encrypted with said second encryption protocol to obtain the plaintext of said digital information within a media memory of said media hardware; encrypting said plaintext within said media memory with a third encryption protocol to produce an encrypted media signal. 
     
     
         114 . The at least one computer readable storage medium of  claim 113 , wherein said instructions when executed further result in the following operations comprising:
 processing said plaintext of said digital information in said secure processing environment into raw frames;   encrypting said raw frames within said secure processing environment to produce encrypted frames; and   transmitting said encrypted frames to said media hardware.   
     
     
         115 . The at least one computer readable storage medium of  claim 114 , wherein said instructions when executed further result in the following operations comprising:
 decrypting said encrypted frames with said media hardware obtain said raw frames in said media memory;   encrypting said raw frames in said media memory with said third encryption protocol to produce said encrypted media signal.   
     
     
         116 . The at least one computer readable storage medium of  claim 113 , wherein said instructions when executed further result in the following operations comprising:
 decrypting said encrypted digital information with one or more decryption keys in a license sealed to said secure processing environment, so as to obtain said plaintext of said digital information within said secure processing environment.   
     
     
         117 . The at least one computer readable storage medium of  claim 113 , wherein a secure video encryption key (SVEK) is stored in said secure processing environment and said media memory, wherein said instructions when executed further result in the following operations comprising:
 using said SVEK in said second encryption protocol to encrypt said plaintext of said digital information within said secure processing environment to produce SVEK encrypted digital information;   transmitting said SVEK encrypted digital information to said media hardware; and   decrypting said SVEK encrypted digital information with said media hardware using said SVEK in said media memory, so as to obtain said plaintext of said digital information within said media memory.   
     
     
         118 . The at least one computer readable storage medium of  claim 117 , wherein said instructions when executed further result in the following operations comprising:
 generating an SVEK with said SVEK issuing authority of said client device; and   transmitting said SVEK from said SVEK issuing authority to said secure processing environment and said media hardware.   
     
     
         119 . The at least one computer readable storage medium of  claim 117 , wherein said SVEK is a temporal SVEK.

Join the waitlist — get patent alerts

Track US2015304736A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.